CVE-2020-10538

MEDIUM

Epikur <20.1.1 - Info Disclosure

Title source: llm
STIX 2.1

Description

An issue was discovered in Epikur before 20.1.1. It stores the secret passwords of the users as MD5 hashes in the database. MD5 can be brute-forced efficiently and should not be used for such purposes. Additionally, since no salt is used, rainbow tables can speed up the attack.

Scores

CVSS v3 5.5
EPSS 0.0003
EPSS Percentile 7.6%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

Details

CWE
CWE-916
Status published
Products (1)
epikur/epikur < 20.1.1
Published Feb 05, 2021
Tracked Since Feb 18, 2026